Polymarket’s U.S. prediction platform faced an attempted $10 million fraud scheme in February 2026 using stolen debit cards, according to an investigation published by The Wall Street Journal. Chief Executive Shayne Coplan urged staff to prioritize growth over compliance, prompting internal alarm, key resignations, and subsequent security overhauls.
The February Fraud Surge and Payment Processor Alarms
Criminals flooded Polymarket’s American platform in February 2026 by linking stolen debit cards to thousands of newly created accounts, placing rapid wagers, and attempting to route winnings onto clean payment instruments. The illicit activity aimed to siphon at least $10 million through the prediction market, according to The Wall Street Journal investigation.
Checkout.com, the payment processor handling debit-card deposits for Polymarket US, flagged the sudden surge and at one point rejected more than 80% of transactions as fraudulent. That rejection rate dwarfed the typical industry standard of roughly 1%. The attack was heavily concentrated among a small group of users, with one individual attempting approximately 4,000 separate deposits.
While thieves tried to make off with at least $10 million, investigators did not establish the exact sum that successfully left the platform, and one person familiar with the matter noted that most attempted deposits ultimately failed.
Executive Pushback and Growth at All Costs
When compliance personnel brought the alarming fraud data to Chief Executive Shayne Coplan, his response stunned staff. According to people familiar with the exchange, Coplan told employees to keep growing the platform and simply pay a regulatory fine if authorities ever caught up. Current and former staff described the reaction as representative of a broader internal culture prioritizing expansion above risk controls.

To accelerate transaction speeds and reduce customer friction on Discord, leadership removed a standard financial safeguard requiring funds deposited from one payment method to be withdrawn back to the same source. Employees warned that dropping this same-source withdrawal rule opened a potential money-laundering pathway, but executives maintained that other internal checks were adequate.
Leadership Departures and Compliance Overhauls
The internal friction culminated in high-profile departures. Andrew Clifford, the Chief Compliance Officer for Polymarket US, resigned in April 2026 after submitting a detailed internal report outlining the platform’s fraud vulnerabilities. Shortly afterward, Polymarket fired Justin Hertzberg, CEO of the U.S. division, alongside the heads of American regulation and anti-money laundering.

Law firm Sullivan & Cromwell subsequently concluded that the company had complied with regulations, according to people familiar with the review. To restore institutional trust, Polymarket brought in new personnel and tighter technical controls. The company limited the number of debit cards a single user could link and hired Riskified for anti-fraud screening and a former FBI agent for anti-fraud.
Funding Push and Regulatory Scrutiny
The compliance test arrives as Polymarket pursues a major funding round targeting roughly $1 billion in fresh capital at a valuation of about $21 billion.
External regulatory pressures continue to mount alongside the financial expansion. The Commodity Futures Trading Commission is investigating the platform, following a 2022 civil penalty of $1.4 million for offering binary options without required registration.
Legal experts contrasted Polymarket’s rapid scaling with traditional financial markets. In the regulated space, this kind of thing does not happen,
said Joe Konizeski, a former CFTC enforcement lawyer, noting that regulated exchanges rely on experienced adults to handle customer funds appropriately.
Worth a look